Issue #276

Monday · August 31, 2026

🥖 Palate Cleanser

After the IAM Roles Manager drama, some really nice folks from AWS finally reached out to chat. Turns out they do understand that rolling opposite-of-least-privilege is a bad idea but they're just hamstrung by product rollout sequencing. Not great, but also not the disaster I worried about. You've already seen some of what's coming but expect pretty dramatic changes in how people sign up and start interacting with AWS for the first time.

I think we have enough evidence now that AI is pretty good at escape rooms. Either the escape rooms need to get harder or we need to rethink sandboxing. Trail of Bits gave a cyber-tuned model SSH into a QEMU/KVM VM and told it to get out. It escaped three times, finishing with several 0-days it found itself after the host was rebuilt from latest upstream, while the researcher's main contribution was power-cycling the box every time the agent hardlocked the kernel.

Enjoy 4 chef's selections today instead of 3. I'm a rebel without a cause.

📋 Chef's selections

AWSHound: An OpenSource AWS OpenGraph Collector

by Julian Catrambone

BloodHound turns Active Directory permissions into a graph, so finding a path to domain admin becomes a database query instead of a manual audit. People have been trying to bring this idea to AWS for years. dAWShund did it by asking AWS itself, one SimulatePrincipalPolicy call at a time, which is accurate but apparently noisy, and only sees identity and resource policies. AWSHound is an offline implementation that decides each edge locally, treating a permissions boundary as a ceiling and evaluating SCPs and RCPs. In one real run it turned more than 500 accounts into 10.5 million edges in about fifteen minutes of processing.

Data Exfiltration from Amazon Kiro via Prompt Injection

by Fergal Glynn

I feel like I've been writing about AI-assisted development tools doing crazy stuff every other week for months. Can't stop now. Aaron got Kiro to read an index.md planted in a workspace the victim opened, go hunting through the repo for a .env, and write what it found into the workspace's own kiroAgent.powersRecommendationUrl setting, at which point the IDE itself fetched the attacker's endpoint with an OPENAI_API_KEY in the query string. Amazon fixed it and paid a $40 Amazon merchandise gift certificate...

A Wildberries Architected Framework

by Chris Farris

In March, missiles took out two of the three availability zones in AWS's Middle East (UAE) region, and nearly six months later both me-central-1 and me-south-1 apparently still cannot reliably run customer workloads. Chris' point is that in Europe the targets would never be hard to find, because a facility pulling tens of megawatts needs a grid interconnection, shows up on any decent satellite pass, and, unlike in the US, goes through planning approval with a public objection period. Maybe it's time to factor geopolitics, not just latency, into how you pick your regions.

I lost my mind doing an AWS external access review

by Daniel Grzelak

Doing an external access review in AWS really shouldn't be this hard but if you take 2-pizza to the extreme, this is what you get. In case you ever try to do it yourself, this post will either guide you through all the inconsistencies and edge cases, or help you realize it's a bad idea to try.

🥗 AWS security blogs

🍛 Reddit threads on r/aws


🤖 Dessert

Every machine-tracked change this week. Nobody else assembles this.

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

☕ CloudFormation resource changes

No resource updates this week.

🎮 Amazon Linux vulnerabilities

📺 AWS security bulletins

🚬 Security documentation changes

No changes this week.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.